Automatic login must be disabled.

From MAC OSX 10.6 Workstation Security Technical Implementation Guide

Part of OSX00425-Disable automatic login

Associated with IA controls: IAAC-1

SV-37251r1_rule Automatic login must be disabled.

Vulnerability discussion

Disabling automatic login is necessary for any level of security. If automatic login is enabled, an intruder can log in without authenticating. Even automatically logging in with a restricted user account, it is still easier to perform malicious actions on the computer.

Check content

1. Open System Preferences->Security. 2. Select General tab. 3. Ensure "Disable automatic login" option is checked. If option is not checked, this is a finding.

Fix text

1. Open System Preferences->Security. 2. Select General tab. 3. Select "Disable automatic login".

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer